Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

HIGH Severity CVEs

CVSS 7.0 – 8.9

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

143,102
Total
363
Known Exploited
Showing 73,421 of 143,102 total · Page 10/1469
8.8
CVE-2026-75977

The Mang Board WP plugin for WordPress is vulnerable to Missing Authorization via Authentication Cookie Forgery in all v

7.5
CVE-2026-18884

The WooCommerce Lottery plugin for WordPress is vulnerable to Time-Based SQL Injection via 'orderby' and 'order' GET Par

7.2
CVE-2026-18331

The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More plugin for WordPress is vul

8.7
CVE-2026-77693

The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the user requesting a file

7.7
CVE-2026-75797

The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local filesyste

7.5
CVE-2026-74928

The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes, allowing

7.2
CVE-2026-74851

The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of blocked func

7.8
CVE-2026-58097

mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the

8.8
CVE-2026-58096

LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by

8.8
CVE-2026-58095

mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a

7.8
CVE-2026-58094

The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory object. This is intended to

7.0
CVE-2026-58093

The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty loc

7.2
CVE-2026-19760

The WP Fastest Cache – WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTTP

8.1
CVE-2026-19718

The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before

8.8
CVE-2026-80202

Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions

7.5
CVE-2026-80198

Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allo

7.5
CVE-2026-80196

Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after passwo

8.8
CVE-2026-80193

Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new t

8.1
CVE-2026-80192

@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) con

7.5
CVE-2026-80191

GROWI applies its page-viewer permission check to attachment requests only when the request carries an authenticated use

7.8
CVE-2026-76148

CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the affected product.

8.1
CVE-2026-58092

In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was st

7.8
CVE-2026-58091

The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If locking a channel would

7.8
CVE-2026-58090

The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket b

7.8
CVE-2026-58089

When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivi

7.7
CVE-2026-57171

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions

7.8
CVE-2026-57170

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions

7.0
CVE-2026-54467

On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 ac

7.6
CVE-2026-29988

A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device mo

8.3
CVE-2026-79912

A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTi

7.8
CVE-2026-54757

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions

7.4
CVE-2026-41707

Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDec

8.1
CVE-2026-18985

Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in

7.5
CVE-2026-18259

Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token

7.6
CVE-2026-80186

A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bl

7.3
CVE-2026-79845

A vulnerability was identified in code-projects Simple Inventory System 1.0. This vulnerability affects unknown code of

7.3
CVE-2026-79804

A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affec

7.5
CVE-2026-68763

Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking w

8.1
CVE-2026-68569

Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that

8.1
CVE-2026-66422

Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as r

7.5
CVE-2026-65927

Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing t

8.1
CVE-2026-65183

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allow

8.3
CVE-2026-79292

Integer overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the

7.4
CVE-2026-79286

Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to po

8.8
CVE-2026-79266

Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineeri

8.1
CVE-2026-79263

Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code

8.3
CVE-2026-79256

Externally controlled reference in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attack

8.3
CVE-2026-79247

Use after free in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker who had com

7.7
CVE-2026-79245

Use after free in UI in Google Chrome prior to 152.0.7977.65 allowed a local attacker who had compromised the renderer p

8.8
CVE-2026-79244

Use after free in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code

Frequently Asked Questions

What does HIGH severity mean for CVEs?

CVSS 7.0–8.9 — serious vulnerabilities that can lead to significant data exposure, privilege escalation, or service disruption

How many high severity CVEs exist?

There are 143,102 CVE records rated HIGH in our database. Of these, 363 are listed in CISA's Known Exploited Vulnerabilities catalog.

How should I prioritize high severity vulnerabilities?

HIGH severity vulnerabilities should be patched immediately, especially if they are in the CISA KEV catalog or have a high EPSS score. Use CyberStrike to automatically detect and prioritize these vulnerabilities across your infrastructure.

Detect HIGH Vulnerabilities

CyberStrike scans your infrastructure and detects high severity vulnerabilities in real time.

Get Started